tlwebaccess (and tlwebadm) are not general web servers. As such, it's mostly just noise to log each and every HTTP request made to them. It is likely quite sufficient to just log the higher level activities (user created a session, user failed to authenticate, etc.). Right now, it can be difficult to find the relevant things among all access log lines. We're also less likely to have issues like bug 8398 if we don't log casual details.